Easy Prey
A familiar voice on the phone or a recognizable face on a video call used to offer some reassurance that you knew who you were dealing with. AI has changed that. Voice cloning, face swaps, and real-time video impersonation now allow scammers to convincingly pose as executives, job candidates, romantic interests, or even family members. Understanding how these attacks work and where they may be headed is a central part of Tom Cross's work as Head of Threat Research at GetReal Security. Tom has spent more than 30 years studying cybersecurity threats, software vulnerabilities, and the methods attackers use to exploit technology. Before joining GetReal Security, he held leadership roles at IBM X-Force, Lancope, and Drawbridge Networks, and he has shared his research at major security conferences including Black Hat and DEF CON. His current work focuses on deepfake-enabled social engineering and the development of tools that can detect digital impersonation, including signs that are often too subtle for a person to recognize. In this episode, we learn how little audio is needed to clone someone's voice, why live video is no longer reliable proof of identity, and how deepfakes are being used in romance scams, investment fraud, identity theft, and remote hiring schemes. We also talk about AI agents that can carry on persuasive conversations, adjust their behavior based on a victim's reactions, and repeat those tactics on a massive scale. The discussion offers a revealing look at why familiar advice for spotting fakes is quickly becoming outdated and what individuals and organizations will need to do differently as the technology improves. Show Notes: * [01:05] Tom shares how his early work in vulnerability research led to a career studying sophisticated cybersecurity threats. * [03:32] Running a bulletin board system as a teenager helped spark an enduring interest in hacking and computer security. * [06:11] A look back at early online communities, text-based games, Fidonet, and the pre-internet era. * [09:36] The conversation shifts to deepfake research and the technology being developed to detect manipulated media. * [11:29] Deepfakes are divided into audio, visual, file-based, and real-time forms, each creating different risks. * [15:20] Modern voice clones can fool both people and biometric authentication systems, making specialized detection increasingly important. * [18:30] Virtual backgrounds and other subtle processing artifacts may reveal manipulation even when nothing looks obviously wrong. * [20:31] Deepfake detection has become another cybersecurity arms race as attackers continually improve their methods. * [22:30] Romance scams, investment fraud, remote job schemes, and identity theft are among the growing uses of deepfake technology. * [25:26] Scammers succeed by exploiting desires, expectations, and the human tendency to rationalize warning signs. * [27:56] Large-scale phishing and business email compromise attacks only need a small percentage of targets to respond. * [29:22] Criminal compounds in Southeast Asia use trafficked workers and deepfake tools to conduct scams on a massive scale. * [30:27] North Korean remote workers may use stolen identities and shared deepfake personas to secure jobs at American companies. * [33:45] Purpose-built criminal software combines face swapping with appearance-enhancing features designed for romance scams. * [35:05] Common visual tests for identifying deepfakes are becoming unreliable as the technology advances. * [39:24] Emotional investment makes detection even harder because people often explain away signs that something is wrong. * [40:47] Building authentication into the internet could help people determine whether digital content is genuine. * [42:13] AI agents may soon conduct automated scams that respond naturally, apply pressure, and adjust to a victim's behavior. * [45:14] Automation could allow criminals to target hundreds of thousands of people while making impersonation increasingly convincing. * [46:22] Machine learning may create self-improving scams that test countless variations and concentrate on the tactics that work. * [49:18] AI lowers the technical barrier to cybercrime by helping people create tools they could not build on their own. * [51:06] Phones and messaging platforms may eventually require stronger controls as automated calls and texts become more common. * [53:09] Digital signatures, watermarks, and verified content could help distinguish malicious deepfakes from authorized uses. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes [https://podcasts.apple.com/us/podcast/easy-prey/id1488678905] and leave a nice review. Links and Resources: * Podcast Web Page [https://www.easyprey.com/] * Facebook Page [https://www.facebook.com/EasyPreyPodcast] * whatismyipaddress.com [https://whatismyipaddress.com/] * Easy Prey on Instagram [https://www.instagram.com/easypreypodcast/] * Easy Prey on Twitter [https://twitter.com/easypreypodcast] * Easy Prey on LinkedIn [https://www.linkedin.com/company/easy-prey-podcast/] * Easy Prey on YouTube [https://www.youtube.com/channel/UCCgy_xKrjiXghSgGFEAFdTQ] * Easy Prey on Pinterest [https://www.pinterest.com/easypreypodcast/] * GetReal Security [https://www.getrealsecurity.com/] * Tom Cross - LinkedIn [https://www.linkedin.com/in/tom-cross-/]
337 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Easy Prey!